CVE-2026-25572: Medium severity Siemens SICAM SIAPP SDK vulnerability
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK server component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially causing denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25572?
CVE-2026-25572 is considered a high severity vulnerability due to the potential for remote exploitation leading to a denial of service.
How do I fix CVE-2026-25572?
To fix CVE-2026-25572, upgrade the SICAM SIAPP SDK to version 2.1.7 or later.
What systems are affected by CVE-2026-25572?
CVE-2026-25572 affects all versions of the Siemens SICAM SIAPP SDK prior to version 2.1.7.
What type of attack does CVE-2026-25572 enable?
CVE-2026-25572 enables attackers to send oversized inputs that may cause a stack overflow, potentially crashing the server.
Is there a workaround for CVE-2026-25572?
Currently, there are no documented workarounds for CVE-2026-25572; the best mitigation is to apply the software update.